An SQL injection vulnerability exists in the management interface of Zingbox Inspector versions 1.288 and earlier, that allows for unsanitized data provided by an authenticated user to be passed from the web UI into the database.

Published : 2019-10-09 21:15 Updated : 2019-10-11 14:32

Score 6.5 / 10
Zingbox Inspector 1.288 cpe:/a:zingbox:inspector:1.288
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') The software constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. CVE

2019-10-11 14:32
2019-10-09 21:15